> ## Documentation Index
> Fetch the complete documentation index at: https://anaconda.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# What is a policy?

export const DefinitionDescription = ({children}) => <dd className="definition-description">{children}</dd>;

export const DefinitionTerm = ({children}) => <dt className="definition-term">{children}</dt>;

export const DefinitionList = ({children}) => <dl className="definition-list">{children}</dl>;

A policy is a governance rule attached to a [perimeter](/docs/platform/concepts/what-is-a-perimeter) that controls what the [workloads](/docs/platform/concepts/what-is-a-workload) in it can access. Policies are how your organization sets guardrails on packages, models, compute, and container images, so that secure, approved access is the default rather than something each user configures.

## Why policies matter

Governance only works if it's enforced consistently. Instead of relying on every data scientist to configure things correctly, an administrator defines policies once, at the perimeter level, and the platform applies them to every workload that runs in that perimeter. This gives your organization central control while keeping the experience simple for users, who work within the guardrails without having to manage them.

Policies are enforced by the platform when a workload is admitted to run. A user cannot bypass a policy from their own code or environment.

## Kinds of policy

Different policies govern different resources:

<DefinitionList>
  <DefinitionTerm>
    Channel policies
  </DefinitionTerm>

  <DefinitionDescription>
    Filter which packages are available from a perimeter's [channels](/docs/platform/concepts/what-is-a-channel), for example by excluding packages with known vulnerabilities or disallowed licenses.
  </DefinitionDescription>

  <DefinitionTerm>
    Model access policies
  </DefinitionTerm>

  <DefinitionDescription>
    Control which models from the [model catalog](/docs/platform/concepts/what-is-the-model-catalog) a perimeter can browse and download, based on conditions such as publisher, license, or size.
  </DefinitionDescription>

  <DefinitionTerm>
    Task resource limits
  </DefinitionTerm>

  <DefinitionDescription>
    Cap the CPU and memory that each task in a perimeter can request, and set the defaults for tasks that don't specify their own.
  </DefinitionDescription>

  <DefinitionTerm>
    Image allowlist
  </DefinitionTerm>

  <DefinitionDescription>
    Restrict which container images tasks in a perimeter can run, and set the default image for tasks that don't specify one.
  </DefinitionDescription>
</DefinitionList>

## How policies are applied

Because policies live on the perimeter, they apply automatically to everything that runs there. When the platform resolves packages for a workload, channel policies determine which packages it can draw on. When a user browses the model catalog, model access policies determine which models they see. When a run starts, task resource limits and the image allowlist determine what its tasks can request and run. Administrators can adjust a perimeter's policies at any time, and the changes apply to subsequent work in that perimeter.

## Managing policies

Policies are configured per perimeter. For configuration details, see [Channel governance](/docs/platform/guides/governance/channel-governance) and [Model governance](/docs/platform/guides/governance/model-governance).
